Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-27305HIGHColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.0%CVE-2026-48310HIGHAdobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.0%CVE-2025-11939MEDIUMChurchCRM Backup Restore RestoreJob.php path traversalEPSS 1.0%CVE-2020-18330CRITICALAn issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2EPSS 1.0%CVE-2023-25345HIGHDirectory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the includeEPSS 1.0%CVE-2024-1303MEDIUMMultiple Vulnerabilities in Badger Meter's MonitoolEPSS 1.0%CVE-2025-0493CRITICALMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File InclusionEPSS 1.0%CVE-2022-36081HIGHWikmd vulnerable to Local File Enumeration when accessing /listEPSS 1.0%CVE-2023-49508MEDIUMDirectory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtaiEPSS 1.0%CVE-2024-48019MEDIUMApache Doris: allows admin users to read arbitrary files through the REST APIEPSS 1.0%CVE-2026-32060HIGHOpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted PathsEPSS 1.0%CVE-2022-23609HIGHPath traveresal in iTunesRPC-RemasteredEPSS 1.0%CVE-2026-9843HIGHDatabase for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST ValueEPSS 1.0%CVE-2024-11123MEDIUM上海灵当信息科技有限公司 Lingdang CRM pdf.php path traversalEPSS 1.0%CVE-2021-43930MEDIUMElcomplus SmartPtt Path TraversalEPSS 1.0%CVE-2026-71932MEDIUMDrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileEPSS 1.0%CVE-2022-0072MEDIUMDirectory Traversal in OpenLiteSpeed Web ServerEPSS 1.0%CVE-2022-3060HIGHImproper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attackeEPSS 1.0%CVE-2026-78461HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2025-34181HIGHNetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCEEPSS 1.0%